Skip to content

Complete signed v1 release acceptance #1

Description

@leanderrj

This tracks the credential- and hardware-dependent gates that cannot be completed from an unsigned development checkout.

Completed in the repository:

  • Install the Sparkle EdDSA private key as an Actions secret.
  • Validate unsigned universal packaging, Sparkle appcast generation, and the generated Homebrew cask in CI.
  • Exercise the 100 MiB / 1.39 million-row performance suite and publish its artifact.
  • Add fail-closed signing, notarization, release attestation, immutable-release verification, and cask-update automation.

Remaining release gates:

  • Add DEVELOPER_ID_P12, DEVELOPER_ID_PASSWORD, APPLE_TEAM_ID, APPLE_ID, and APPLE_APP_PASSWORD without exposing their values.
  • Run and approve the manual notarized v1.0.0 release-candidate workflow.
  • Install the candidate on clean Apple Silicon and Intel Macs.
  • Exercise save/reopen, malformed recovery, Undo/Redo, clipboard operations, VoiceOver, and light/dark appearance.
  • Verify a Sparkle update from an older signed build to the v1 candidate.
  • Re-run the generated Homebrew cask audit against the notarized DMG.
  • Move CHANGELOG entries to 1.0.0 and publish an annotated v1.0.0 tag only after every gate is green.

The release workflow fails closed if any credential is missing or mismatched. No v1 tag or GitHub release should be created before these gates pass.

Metadata

Metadata

Assignees

No one assigned

    Labels

    automationCI and release automation

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions